Key Management (SSS)
How LearnCard protects private keys using Shamir Secret Sharing
What is this section about?
Why is this important?
How It Works
The 2-of-4 Threshold Scheme
Private Key (32 bytes)
β
βββ Split via Shamir 2-of-4 βββββββββββββββββββββββββββ
β β
βΌ βΌ βΌ βΌ
Device Share Auth Share Recovery Share Email Share
(IndexedDB) (lca-api server, (passkey, phrase, (encrypted email
AES-256-GCM or backup file) backup)
encrypted at rest)
β
Any 2 shares β reconstruct private key ββββββββββββββββββββThe Four Shares
1. Device Share
2. Auth Share (Server Share)
3. Recovery Share
Method
How the share is protected
Storage
4. Email Share
Normal Login (Same Device)
New Device Login
Security Levels
Level
Requirements
Risk Profile
Share Versioning
Server-Side Encryption
Migration from Web3Auth
Key Takeaways
Last updated
Was this helpful?